X
  • About
  • Advertise
  • Contact
  • Events
Subscribe to our Newsletter
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
No Results
View All Results
Home News Super

Trustees on the hook for data security: APRA

APRA has made it clear that super fund trustees are explicitly responsible for the data security of their service providers.

by Tim Stewart
March 8, 2018
in News, Super
Reading Time: 2 mins read
Share on FacebookShare on Twitter

Prudential Standard CPS 234: Information Security has been drafted by the Australian Prudential Regulation Authority (APRA) in an attempt to “minimise the likelihood and impact of information security incidents on the confidentiality, integrity, or availability of information assets.”

This includes information ‘assets’ managed by related parties or third parties.

X

For super funds, which outsource a great deal of their operations to third parties, the proposed changes will heap new responsibilities on trustees’ shoulders.

Under APRA’s prudential guide, super trustees will be responsible for the data security of third parties used for member administration, investment management, insurance, data analytics and custodial services.

In a discussion paper accompanying the prudential standard draft, APRA notes that any outsourcing arrangements involving material business activities must be subject to “appropriate due diligence, approval and ongoing monitoring”.

“In complying with prudential requirements in respect of risks arising from outsourcing material business activities, an entity’s due diligence and ongoing monitoring should include an assessment of the information security capability of the outsourcing provider,” said APRA.

“Draft CPS 234 extends these requirements to include an assessment of the information security capability of all other outsourcing providers, commensurate with the potential consequences of an information security incident.”

Specifically, super trustees will be required to assess the control testing frameworks and audit assurance of outsourcing providers – and, importantly, to notify APRA when they discover information security ‘incidents’ and “control weaknesses”.

The prudential guide comes two weeks into the new mandatory data breach reporting regime, which officially began on 22 February 2018.

Under the new system, financial services providers (including super funds) will be required to report data breaches that are deemed “likely to cause serious harm” to the Office of the Australian Information Commissioner.

Related Posts

Macquarie Securities faces $35m penalty for misleading conduct

by Adrian Suljanovic
December 19, 2025

Macquarie Securities has admitted misleading conduct and systemic reporting failures as ASIC seeks a $35 million penalty in the NSW...

Crypto poised for long-term growth: MHC Digital

by Olivia Grace-Curran
December 19, 2025

Digital assets are entering a pivotal phase of maturity, with 2026 expected to mark a decisive year for institutional adoption,...

Regulatory action to be private credit tailwind in 2026

by Georgie Preston
December 19, 2025

Private credit has successfully demonstrated its “durability” in the last 12 months, according to Metrics Credit Partners, with the firm flagging multiple positive...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Why U.S. middle market private credit is a powerful income solution for Australian institutional investors

In today’s investment landscape, middle market direct lending, a key segment of private credit, has emerged as an attractive option...

by Tim Warrick
December 2, 2025
Promoted Content

Is Your SMSF Missing Out on the Crypto Boom?

Digital assets are the fastest-growing investment in SMSFs. Swyftx's expert team helps you securely and compliantly add crypto to your...

by Swyftx
December 2, 2025
Promoted Content

Global dividends reach US$519 billion, what’s behind the rise?

Global dividends surged to a record US$518.7 billion in Q3 2025, up 6.2% year-on-year, with financials leading the way. The...

by Capital Group
November 18, 2025
Promoted Content

Why smaller can be smarter in private credit

Over the past 15 years, middle market direct lending has grown into one of the most dynamic areas of alternative...

by Tim Warrick, Managing Director of Principal Alternative Credit, Principal Asset Management
November 14, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Latest Podcast

Podcast

Relative Return Insider: MYEFO, US data and a 2025 wrap up

by Staff Writer
December 18, 2025
After more than two decades, InvestorDaily continues to be an institution that connects and influences Australia’s financial services sector. This influential and integrated media brand connects with leading financial services professionals within superannuation, funds management, financial planning and intermediary distribution through a range of channels, including digital, social, research, broadcast, webcast and events.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Markets
  • Appointments
  • Regulation
  • Super
  • Mergers & Acquisitions
  • Tech
  • Promoted Content
  • Analysis

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Markets
  • Regulation
  • Super
  • M&A
  • Tech
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited